Browse 1,193 controls and enhancements across 20 security and privacy families. Use the GovRAMP crosswalk to locate controls referenced by Security Snapshot, Core, and Moderate.
A shared catalog supports common-control planning; designation as a common, hybrid, or system-specific control depends on your organization’s implementation and inheritance decisions.
System and Information Integrity · Enhancement
SI-12(1) · Limit Personally Identifiable Information Elements
View parent controlControl statement and discussion
NIST control statement
Limit personally identifiable information being processed in the information life cycle to the following elements of personally identifiable information: [Assignment: elements of personally identifiable information].
Discussion
Limiting the use of personally identifiable information throughout the information life cycle when the information is not needed for operational purposes helps to reduce the level of privacy risk created by a system. The information life cycle includes information creation, collection, use, processing, storage, maintenance, dissemination, disclosure, and disposition. Risk assessments as well as applicable laws, regulations, and policies can provide useful inputs to determining which elements of personally identifiable information may create risk.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
System and Information Integrity · Enhancement
SI-12(2) · Minimize Personally Identifiable Information in Testing, Training, and Research
View parent controlControl statement and discussion
NIST control statement
Use the following techniques to minimize the use of personally identifiable information for research, testing, or training: [Assignment: organization-defined techniques].
Discussion
Organizations can minimize the risk to an individual’s privacy by employing techniques such as de-identification or synthetic data. Limiting the use of personally identifiable information throughout the information life cycle when the information is not needed for research, testing, or training helps reduce the level of privacy risk created by a system. Risk assessments as well as applicable laws, regulations, and policies can provide useful inputs to determining the techniques to use and when to use them.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
System and Information Integrity · Enhancement
SI-12(3) · Information Disposal
View parent controlControl statement and discussion
NIST control statement
Use the following techniques to dispose of, destroy, or erase information following the retention period: [Assignment: organization-defined techniques].
Discussion
Organizations can minimize both security and privacy risks by disposing of information when it is no longer needed. The disposal or destruction of information applies to originals as well as copies and archived records, including system logs that may contain personally identifiable information.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
System and Information Integrity · Base control
SI-13 · Predictable Failure Prevention
Control statement and discussion
NIST control statement
a. Determine mean time to failure (MTTF) for the following system components in specific environments of operation: [Assignment: system components] ; and
b. Provide substitute system components and a means to exchange active and standby components in accordance with the following criteria: [Assignment: mean time to failure (MTTF) substitution criteria].
Discussion
While MTTF is primarily a reliability issue, predictable failure prevention is intended to address potential failures of system components that provide security capabilities. Failure rates reflect installation-specific consideration rather than the industry-average. Organizations define the criteria for the substitution of system components based on the MTTF value with consideration for the potential harm from component failures. The transfer of responsibilities between active and standby components does not compromise safety, operational readiness, or security capabilities. The preservation of system state variables is also critical to help ensure a successful transfer process. Standby components remain available at all times except for maintenance issues or recovery failures in progress.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
System and Information Integrity · Enhancement
SI-13(1) · Transferring Component Responsibilities
View parent controlControl statement and discussion
NIST control statement
Take system components out of service by transferring component responsibilities to substitute components no later than [Assignment: fraction or percentage] of mean time to failure.
Discussion
Transferring primary system component responsibilities to other substitute components prior to primary component failure is important to reduce the risk of degraded or debilitated mission or business functions. Making such transfers based on a percentage of mean time to failure allows organizations to be proactive based on their risk tolerance. However, the premature replacement of system components can result in the increased cost of system operations.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
System and Information Integrity · Enhancement
SI-13(3) · Manual Transfer Between Components
View parent controlControl statement and discussion
NIST control statement
Manually initiate transfers between active and standby system components when the use of the active component reaches [Assignment: percentage] of the mean time to failure.
Discussion
For example, if the MTTF for a system component is 100 days and the MTTF percentage defined by the organization is 90 percent, the manual transfer would occur after 90 days.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
System and Information Integrity · Enhancement
SI-13(4) · Standby Component Installation and Notification
View parent controlControl statement and discussion
NIST control statement
If system component failures are detected:
(a) Ensure that the standby components are successfully and transparently installed within [Assignment: time period] ; and
(b) [Selection (one-or-more): activate [Assignment: alarm] ; automatically shut down the system; [Assignment: action] ].
Discussion
Automatic or manual transfer of components from standby to active mode can occur upon the detection of component failures.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
System and Information Integrity · Enhancement
SI-13(5) · Failover Capability
View parent controlControl statement and discussion
NIST control statement
Provide [Selection (one): real-time; near real-time] [Assignment: failover capability] for the system.
Discussion
Failover refers to the automatic switchover to an alternate system upon the failure of the primary system. Failover capability includes incorporating mirrored system operations at alternate processing sites or periodic data mirroring at regular intervals defined by the recovery time periods of organizations.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
System and Information Integrity · Base control
SI-14 · Non-persistence
Control statement and discussion
NIST control statement
Implement non-persistent [Assignment: system components and services] that are initiated in a known state and terminated [Selection (one-or-more): upon end of session of use; [Assignment: frequency] ].
Discussion
Implementation of non-persistent components and services mitigates risk from advanced persistent threats (APTs) by reducing the targeting capability of adversaries (i.e., window of opportunity and available attack surface) to initiate and complete attacks. By implementing the concept of non-persistence for selected system components, organizations can provide a trusted, known state computing resource for a specific time period that does not give adversaries sufficient time to exploit vulnerabilities in organizational systems or operating environments. Since the APT is a high-end, sophisticated threat with regard to capability, intent, and targeting, organizations assume that over an extended period, a percentage of attacks will be successful. Non-persistent system components and services are activated as required using protected information and terminated periodically or at the end of sessions. Non-persistence increases the work factor of adversaries attempting to compromise or breach organizational systems.
Non-persistence can be achieved by refreshing system components, periodically reimaging components, or using a variety of common virtualization techniques. Non-persistent services can be implemented by using virtualization techniques as part of virtual machines or as new instances of processes on physical machines (either persistent or non-persistent). The benefit of periodic refreshes of system components and services is that it does not require organizations to first determine whether compromises of components or services have occurred (something that may often be difficult to determine). The refresh of selected system components and services occurs with sufficient frequency to prevent the spread or intended impact of attacks, but not with such frequency that it makes the system unstable. Refreshes of critical components and services may be done periodically to hinder the ability of adversaries to exploit optimum windows of vulnerabilities.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
System and Information Integrity · Enhancement
SI-14(1) · Refresh from Trusted Sources
View parent controlControl statement and discussion
NIST control statement
Obtain software and data employed during system component and service refreshes from the following trusted sources: [Assignment: trusted sources].
Discussion
Trusted sources include software and data from write-once, read-only media or from selected offline secure storage facilities.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
System and Information Integrity · Enhancement
SI-14(2) · Non-persistent Information
View parent controlControl statement and discussion
NIST control statement
(a) [Selection (one): refresh [Assignment: information] [Assignment: frequency] ; generate [Assignment: information] on demand] ; and
(b) Delete information when no longer needed.
Discussion
Retaining information longer than is needed makes the information a potential target for advanced adversaries searching for high value assets to compromise through unauthorized disclosure, unauthorized modification, or exfiltration. For system-related information, unnecessary retention provides advanced adversaries information that can assist in their reconnaissance and lateral movement through the system.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
System and Information Integrity · Enhancement
SI-14(3) · Non-persistent Connectivity
View parent controlControl statement and discussion
NIST control statement
Establish connections to the system on demand and terminate connections after [Selection (one): completion of a request; a period of non-use].
Discussion
Persistent connections to systems can provide advanced adversaries with paths to move laterally through systems and potentially position themselves closer to high value assets. Limiting the availability of such connections impedes the adversary’s ability to move freely through organizational systems.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
System and Information Integrity · Base control
SI-15 · Information Output Filtering
Control statement and discussion
NIST control statement
Validate information output from the following software programs and/or applications to ensure that the information is consistent with the expected content: [Assignment: software programs and/or applications].
Discussion
Certain types of attacks, including SQL injections, produce output results that are unexpected or inconsistent with the output results that would be expected from software programs or applications. Information output filtering focuses on detecting extraneous content, preventing such extraneous content from being displayed, and then alerting monitoring tools that anomalous behavior has been discovered.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
System and Information Integrity · Base control
SI-16 · Memory Protection
Control statement and discussion
NIST control statement
Implement the following controls to protect the system memory from unauthorized code execution: [Assignment: controls].
Discussion
Some adversaries launch attacks with the intent of executing code in non-executable regions of memory or in memory locations that are prohibited. Controls employed to protect memory include data execution prevention and address space layout randomization. Data execution prevention controls can either be hardware-enforced or software-enforced with hardware enforcement providing the greater strength of mechanism.
GovRAMP crosswalk
- GovRAMP Moderate Readiness · SI-16 — Direct NIST identifier reference. GovRAMP source matrix
System and Information Integrity · Base control
SI-17 · Fail-safe Procedures
Control statement and discussion
NIST control statement
Implement the indicated fail-safe procedures when the indicated failures occur: [Assignment: organization-defined list of failure conditions and associated fail-safe procedures].
Discussion
Failure conditions include the loss of communications among critical system components or between system components and operational facilities. Fail-safe procedures include alerting operator personnel and providing specific instructions on subsequent steps to take. Subsequent steps may include doing nothing, reestablishing system settings, shutting down processes, restarting the system, or contacting designated organizational personnel.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
System and Information Integrity · Base control
SI-18 · Personally Identifiable Information Quality Operations
Control statement and discussion
NIST control statement
a. Check the accuracy, relevance, timeliness, and completeness of personally identifiable information across the information life cycle [Assignment: organization-defined frequency] ; and
b. Correct or delete inaccurate or outdated personally identifiable information.
Discussion
Personally identifiable information quality operations include the steps that organizations take to confirm the accuracy and relevance of personally identifiable information throughout the information life cycle. The information life cycle includes the creation, collection, use, processing, storage, maintenance, dissemination, disclosure, and disposal of personally identifiable information. Personally identifiable information quality operations include editing and validating addresses as they are collected or entered into systems using automated address verification look-up application programming interfaces. Checking personally identifiable information quality includes the tracking of updates or changes to data over time, which enables organizations to know how and what personally identifiable information was changed should erroneous information be identified. The measures taken to protect personally identifiable information quality are based on the nature and context of the personally identifiable information, how it is to be used, how it was obtained, and the potential de-identification methods employed. The measures taken to validate the accuracy of personally identifiable information used to make determinations about the rights, benefits, or privileges of individuals covered under federal programs may be more comprehensive than the measures used to validate personally identifiable information used for less sensitive purposes.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
System and Information Integrity · Enhancement
SI-18(1) · Automation Support
View parent controlControl statement and discussion
NIST control statement
Correct or delete personally identifiable information that is inaccurate or outdated, incorrectly determined regarding impact, or incorrectly de-identified using [Assignment: automated mechanisms].
Discussion
The use of automated mechanisms to improve data quality may inadvertently create privacy risks. Automated tools may connect to external or otherwise unrelated systems, and the matching of records between these systems may create linkages with unintended consequences. Organizations assess and document these risks in their privacy impact assessments and make determinations that are in alignment with their privacy program plans.
As data is obtained and used across the information life cycle, it is important to confirm the accuracy and relevance of personally identifiable information. Automated mechanisms can augment existing data quality processes and procedures and enable an organization to better identify and manage personally identifiable information in large-scale systems. For example, automated tools can greatly improve efforts to consistently normalize data or identify malformed data. Automated tools can also be used to improve the auditing of data and detect errors that may incorrectly alter personally identifiable information or incorrectly associate such information with the wrong individual. Automated capabilities backstop processes and procedures at-scale and enable more fine-grained detection and correction of data quality errors.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
System and Information Integrity · Enhancement
SI-18(2) · Data Tags
View parent controlControl statement and discussion
NIST control statement
Employ data tags to automate the correction or deletion of personally identifiable information across the information life cycle within organizational systems.
Discussion
Data tagging personally identifiable information includes tags that note processing permissions, authority to process, de-identification, impact level, information life cycle stage, and retention or last updated dates. Employing data tags for personally identifiable information can support the use of automation tools to correct or delete relevant personally identifiable information.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
System and Information Integrity · Enhancement
SI-18(3) · Collection
View parent controlControl statement and discussion
NIST control statement
Collect personally identifiable information directly from the individual.
Discussion
Individuals or their designated representatives can be sources of correct personally identifiable information. Organizations consider contextual factors that may incentivize individuals to provide correct data versus false data. Additional steps may be necessary to validate collected information based on the nature and context of the personally identifiable information, how it is to be used, and how it was obtained. The measures taken to validate the accuracy of personally identifiable information used to make determinations about the rights, benefits, or privileges of individuals under federal programs may be more comprehensive than the measures taken to validate less sensitive personally identifiable information.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
System and Information Integrity · Enhancement
SI-18(4) · Individual Requests
View parent controlControl statement and discussion
NIST control statement
Correct or delete personally identifiable information upon request by individuals or their designated representatives.
Discussion
Inaccurate personally identifiable information maintained by organizations may cause problems for individuals, especially in those business functions where inaccurate information may result in inappropriate decisions or the denial of benefits and services to individuals. Even correct information, in certain circumstances, can cause problems for individuals that outweigh the benefits of an organization maintaining the information. Organizations use discretion when determining if personally identifiable information is to be corrected or deleted based on the scope of requests, the changes sought, the impact of the changes, and laws, regulations, and policies. Organizational personnel consult with the senior agency official for privacy and legal counsel regarding appropriate instances of correction or deletion.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
System and Information Integrity · Enhancement
SI-18(5) · Notice of Correction or Deletion
View parent controlControl statement and discussion
NIST control statement
Notify [Assignment: recipients] and individuals that the personally identifiable information has been corrected or deleted.
Discussion
When personally identifiable information is corrected or deleted, organizations take steps to ensure that all authorized recipients of such information, and the individual with whom the information is associated or their designated representatives, are informed of the corrected or deleted information.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
System and Information Integrity · Base control
SI-19 · De-identification
Control statement and discussion
NIST control statement
a. Remove the following elements of personally identifiable information from datasets: [Assignment: elements] ; and
b. Evaluate [Assignment: frequency] for effectiveness of de-identification.
Discussion
De-identification is the general term for the process of removing the association between a set of identifying data and the data subject. Many datasets contain information about individuals that can be used to distinguish or trace an individual’s identity, such as name, social security number, date and place of birth, mother’s maiden name, or biometric records. Datasets may also contain other information that is linked or linkable to an individual, such as medical, educational, financial, and employment information. Personally identifiable information is removed from datasets by trained individuals when such information is not (or no longer) necessary to satisfy the requirements envisioned for the data. For example, if the dataset is only used to produce aggregate statistics, the identifiers that are not needed for producing those statistics are removed. Removing identifiers improves privacy protection since information that is removed cannot be inadvertently disclosed or improperly used. Organizations may be subject to specific de-identification definitions or methods under applicable laws, regulations, or policies. Re-identification is a residual risk with de-identified data. Re-identification attacks can vary, including combining new datasets or other improvements in data analytics. Maintaining awareness of potential attacks and evaluating for the effectiveness of the de-identification over time support the management of this residual risk.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
System and Information Integrity · Enhancement
SI-19(1) · Collection
View parent controlControl statement and discussion
NIST control statement
De-identify the dataset upon collection by not collecting personally identifiable information.
Discussion
If a data source contains personally identifiable information but the information will not be used, the dataset can be de-identified when it is created by not collecting the data elements that contain the personally identifiable information. For example, if an organization does not intend to use the social security number of an applicant, then application forms do not ask for a social security number.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
System and Information Integrity · Enhancement
SI-19(2) · Archiving
View parent controlControl statement and discussion
NIST control statement
Prohibit archiving of personally identifiable information elements if those elements in a dataset will not be needed after the dataset is archived.
Discussion
Datasets can be archived for many reasons. The envisioned purposes for the archived dataset are specified, and if personally identifiable information elements are not required, the elements are not archived. For example, social security numbers may have been collected for record linkage, but the archived dataset may include the required elements from the linked records. In this case, it is not necessary to archive the social security numbers.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
System and Information Integrity · Enhancement
SI-19(3) · Release
View parent controlControl statement and discussion
NIST control statement
Remove personally identifiable information elements from a dataset prior to its release if those elements in the dataset do not need to be part of the data release.
Discussion
Prior to releasing a dataset, a data custodian considers the intended uses of the dataset and determines if it is necessary to release personally identifiable information. If the personally identifiable information is not necessary, the information can be removed using de-identification techniques.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.